Vulnerability Reportportainer/portainer-ce:latest

portainer/portainer-ce:latestportainer/portainer-ce:ltsportainer/portainer-ce:2.39.3
DIGESTsha256:d27f76194b719bfe2a34779d51798a7adf02510cfba69ebcb538267f75aa4f47

Executive Summary

DANGEROUS

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. Exploiting the most severe vulnerability, CVE-2026-45570, could lead to remote code execution on the Portainer host and potential full system compromise. Furthermore, multiple high-context denial-of-service vulnerabilities, including CVE-2026-33814, could render the Portainer web UI unavailable. The critical RCE (CVE-2026-45570) specifically applies when Portainer interacts with Git repositories via SSH transport using specially crafted paths.

Threat Score
75/100
DANGEROUS
Reputation
TRUSTED
portainer
BaseImage/
portainer/portainer-ce:latest
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

36 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45570CRITICAL9.6
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
Directly ExposedContext importance: HIGH
CVE-2026-33814MEDIUM6.38
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39820MEDIUM6.38
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-33814MEDIUM6.38
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39820MEDIUM6.38
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-33997MEDIUM5.5
github.com/docker/docker
v28.5.1+incompatible
fixed in 29.3.1
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34040MEDIUM5.3
github.com/docker/docker
v28.5.1+incompatible
fixed in 29.3.1
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39826LOW3.67
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39826LOW3.67
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33747LOW3
github.com/moby/buildkit
v0.25.1
fixed in 0.28.1
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15558LOW2.45
github.com/docker/cli
v28.5.1+incompatible
fixed in 29.2.0
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-33748LOW2.29
github.com/moby/buildkit
v0.25.1
fixed in 0.28.1
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39836LOW2.29
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-46680NONE0
github.com/containerd/containerd
v1.7.30
fixed in 1.7.32
Not Applicable
CVE-2026-46680NONE0
github.com/containerd/containerd/v2
v2.1.5
fixed in 2.0.9, 2.2.4, 2.3.1
Not Applicable
CVE-2026-41567NONE0
github.com/docker/docker
v28.5.1+incompatible
No fix yet
Not Applicable
CVE-2026-42306NONE0
github.com/docker/docker
v28.5.1+incompatible
No fix yet
Not Applicable
CVE-2026-41568NONE0
github.com/docker/docker
v28.5.1+incompatible
No fix yet
Not Applicable
CVE-2026-45571NONE0
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
Not Applicable
GHSA-w5pp-99ch-qj29NONE0
github.com/go-git/go-git/v5
v5.19.0
fixed in 5.19.1
Not Applicable
CVE-2025-47909NONE0
github.com/gorilla/csrf
v1.7.3
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
Not Applicable